QuestionQ406

Information Security Program

An organization has identified a recurring issue in which insecure code is being released into production. Which of the following actions should the information security manager take?

  • A Implement segregation of duties between development and production.
  • B Increase the frequency of penetration testing.
  • C Review existing configuration management processes.
  • D Review existing change management processes.
Explanation

Change management establishes the controls for reviewing, testing, approving, and deploying software changes into production. Repeated production releases of insecure code indicate that these controls should be assessed for gaps or ineffective enforcement.

Community Discussion

No comments yet. Be the first to start the discussion!